<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/sonicwall-sma1000-zero-days-cve-2026-15409-and-cve-2026-15410-actively-exploited-patches-available-5meaovd0l" -->

---
title: SonicWall SMA1000 zero-days CVE-2026-15409 and...
description: Rapid7&#x27;s MDR team discovered and disclosed two actively exploited zero-day vulnerabilities in SonicWall SMA1000 Series appliances. CVE-2026-15409 (CVSS 10.0)...
canonical: https://daily.dev/posts/sonicwall-sma1000-zero-days-cve-2026-15409-and-cve-2026-15410-actively-exploited-patches-available-5meaovd0l
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 actively exploited, patches available | daily.dev
og:description: Rapid7&#x27;s MDR team discovered and disclosed two actively exploited zero-day vulnerabilities in SonicWall SMA1000 Series appliances. CVE-2026-15409 (CVSS 10.0)...
og:url: https://daily.dev/posts/sonicwall-sma1000-zero-days-cve-2026-15409-and-cve-2026-15410-actively-exploited-patches-available-5meaovd0l
og:image: https://api.daily.dev/og/posts/5MEAOVd0l.png
og:image:alt: SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 actively exploited, patches available
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 actively exploited, patches available

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

Rapid7's MDR team discovered and disclosed two actively exploited zero-day vulnerabilities in SonicWall SMA1000 Series appliances. CVE-2026-15409 (CVSS 10.0) is an unauthenticated SSRF that abuses a websocket proxy to tunnel traffic to localhost services. CVE-2026-15410 is a path traversal flaw enabling local privilege escalation to root. Chained together, they allow unauthenticated remote code execution. Observed attacks included credential harvesting, MFA seed theft, and lateral movement into Active Directory. Affected firmware branches are 12.4.3 and 12.5.0 on SMA1000 models 6210, 7210, and 8200v. SonicWall has released patches with no available workarounds. Both CVEs are in CISA's Known Exploited Vulnerabilities catalog with a July 17 remediation deadline. Rapid7 has published IOCs, log patterns, attacker IP ranges, and a Python proof-of-concept for defenders.

## Content

Two zero-day vulnerabilities in SonicWall's SMA1000 Series remote access appliances have been actively exploited since at least June 22, weeks before public disclosure. Rapid7's MDR team discovered and reported the flaws; Volexity assisted SonicWall in the incident response investigation.

## What the vulnerabilities are

**CVE-2026-15409** (CVSS 10.0) is a Server-Side Request Forgery flaw in the Workplace interface. Specifically, it's an unauthenticated SSRF via a websocket proxy that lets attackers tunnel to arbitrary localhost services, including CouchDB running on the appliance.

**CVE-2026-15410** is a path traversal-based code injection vulnerability in the Appliance Management Console (AMC). It allows privilege escalation to root via the `remove_hotfix` workflow.

Chained together, the two flaws enable unauthenticated remote code execution on affected devices. No workarounds exist.

Affected models are the SMA1000 6210, 7210, and 8200v running firmware branches 12.4.3 and 12.5.0. Patches are available in versions 12.4.3-03453 and 12.5.0-02835.

## What attackers actually did

Volexity attributed the attacks to a threat actor they track as UTA0533. The observed attack chain:

1. Exploited the SSRF to reach internal services, including CouchDB, to harvest credentials and steal MFA seeds
2. Used the code injection flaw to gain root access
3. Deployed a custom malware dropper called **KNUCKLEBALL**
4. KNUCKLEBALL installed two Java-based malware families: **Sou5**, a reverse proxy for covert tunneling, and **ORANGETAIL**, a webshell that executes encrypted payloads
5. Also installed **ROOTRUN**, a privilege escalation tool
6. Used the compromised appliance as a foothold for lateral movement into Active Directory

Rapid7 has published IOCs, log patterns, attacker IP ranges, and a Python proof-of-concept. No public PoC existed at initial disclosure.

## What to do

Both CVEs are in CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of July 17. Patch immediately. SonicWall devices have been a recurring target for ransomware groups, and the combination of credential harvesting and AD lateral movement here suggests these intrusions are likely precursors to broader network compromise.

If you're running any SMA1000 appliance on the affected firmware branches and haven't applied the hotfix, assume the window for clean remediation is closing fast.

---

Tags: [#security](https://daily.dev/tags/security), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/sonicwall-sma1000-zero-days-cve-2026-15409-and-cve-2026-15410-actively-exploited-patches-available-5meaovd0l)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 actively exploited, patches available","url":"https://daily.dev/posts/sonicwall-sma1000-zero-days-cve-2026-15409-and-cve-2026-15410-actively-exploited-patches-available-5meaovd0l","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/sonicwall-sma1000-zero-days-cve-2026-15409-and-cve-2026-15410-actively-exploited-patches-available-5meaovd0l"},"datePublished":"2026-07-15T17:42:58.850Z","dateModified":"2026-07-20T22:44:30.741Z","description":"Rapid7's MDR team discovered and disclosed two actively exploited zero-day vulnerabilities in SonicWall SMA1000 Series appliances. CVE-2026-15409 (CVSS 10.0)...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d40a945707a72b51251f68d426fdb283?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/d40a945707a72b51251f68d426fdb283?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/sonicwall-sma1000-zero-days-cve-2026-15409-and-cve-2026-15410-actively-exploited-patches-available-5meaovd0l","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,zero-day","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"SonicWall SMA1000 zero-days CVE-2026-15409 and CVE-2026-15410 actively exploited, patches available"}]}
```

